Legal
Privacy Policy
Last updated: January 2026
Our commitment
UVO Health takes security and privacy very seriously. Our telemedicine platform is equipped with extensive security and encryption protocols to maintain data integrity, and we operate in full compliance with HIPAA, GDPR, PHIPA/PIPEDA and HITECH requirements.
This policy explains what information we collect, why we collect it, and the choices you have about it.
Information we collect
Account information provided when an organization or provider signs up, such as name, email address, phone number, practice details and billing information.
Visit information required to deliver care, including scheduling data, session metadata and - where a provider enables it - recorded sessions.
Technical information such as device type, browser, and log data used to keep sessions secure and reliable.
How we use information
To operate the platform, connect providers with patients, process payments, deliver appointment reminders, provide support, and to detect and prevent abuse or security incidents.
We do not sell personal information or protected health information.
Protected health information
When UVO Health processes protected health information on behalf of a covered entity, we act as a business associate under HIPAA and handle that information according to our Business Associate Agreement and applicable law.
Security
State of the art security and encryption protocols are implemented to assure that data integrity and privacy is maintained, both in transit and at rest. Access to production systems is limited and audited.
Your choices and rights
Depending on your location, you may have rights to access, correct, export or delete personal information. Patients should direct requests concerning their health records to their healthcare provider, who controls that record.
Contact
Questions about this policy or our privacy practices can be sent to our team through the contact link in the site footer.